Re: Object cannot be edited using ADSIEdit

From: Dmitri Gavrilov [MSFT] (dmitrig_at_online.microsoft.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 16:53:22 -0600

Did you add Deny Full Control to everyone or something along these lines?
Use dsacls /S to restore default security on the object. It is possible you
will need to take ownership of the object first. Use ADAM's version of
dsacls with /takeOwnership to do this.

-- 
Dmitri Gavrilov
SDE, Active Directory Core
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
"timg" <tim@deltacompsys.com> wrote in message
news:10e16d02iborpa3@corp.supernews.com...
> I added "Deny" permissions to an address list in Exchange 2003 which are
> stored as AD objects (we have Server 2003 running as AD controller).  I
can
> no longer access the object through exchange.  So I tried to edit the
> permissions from ADSIEdit and I get an error "invalid path".  Also tried
> deleting the object and got another error.
>
> When I export the AD tree that object does not display a class type.  It
> appears that the AD object is seriously corrupted.  Any way to fix this?
>
> Thanx!
>
>


Relevant Pages

  • Re: GetEffectiveRightsFromAcl
    ... > you have an allowed ACE preceding a denied ACE, ... > "Ray Hayes" wrote in message ... The first ACE grants full control. ... >> deny inherited from the parent item and the 3rd is a grant of full control ...
    (microsoft.public.platformsdk.security)
  • Re: folder permissions
    ... groups and something about deny over rides allow. ... groups assigned to this one folder and the same user has diff priv's ... permissions, everyone has full control. ...
    (microsoft.public.windows.server.general)
  • Re: Delgation Question
    ... > Control to their ... This doesn't make sense to me - shouldn't deny take ... When delegating permissions also ...
    (microsoft.public.win2000.active_directory)
  • Re: Registry.Pol
    ... If you change setting in local policy it applies to all accounts. ... You can Deny Full control to an admin account on the directory ...
    (microsoft.public.windowsxp.security_admin)
  • permission on ADAM objects
    ... After execution, cn=dhsdel got the full control on ou=dhs. ... problem is with ldp I am unable to access ou=dhs. ...
    (microsoft.public.windows.server.active_directory)